Show filters
16,626 Total Results
Displaying 341-350 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2025-0680

Disclosure Date: January 30, 2025 (last updated February 27, 2025)
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.
0
Attacker Value
Unknown

CVE-2025-22222

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known.
0
Attacker Value
Unknown

CVE-2025-22221

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performing a delete action in the Agent Configuration.
0
Attacker Value
Unknown

CVE-2025-22220

Disclosure Date: January 30, 2025 (last updated February 27, 2025)
VMware Aria Operations for Logs contains a privilege escalation vulnerability. A malicious actor with non-administrative privileges and network access to Aria Operations for Logs API may be able to perform certain operations in the context of an admin user.
0
Attacker Value
Unknown

CVE-2025-22219

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations as admin user.
0
Attacker Value
Unknown

CVE-2025-22218

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
VMware Aria Operations for Logs contains an information disclosure vulnerability. A malicious actor with View Only Admin permissions may be able to read the credentials of a VMware product integrated with VMware Aria Operations for Logs
0
Attacker Value
Unknown

CVE-2024-13484

Disclosure Date: January 28, 2025 (last updated February 27, 2025)
A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.
0
Attacker Value
Unknown

CVE-2024-8401

Disclosure Date: January 28, 2025 (last updated February 27, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.
0
Attacker Value
Unknown

CVE-2025-0754

Disclosure Date: January 28, 2025 (last updated February 27, 2025)
The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can mislead logging mechanisms, enabling attackers to manipulate log entries or execute reflected cross-site scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2025-0752

Disclosure Date: January 28, 2025 (last updated February 27, 2025)
A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.
0